The purpose of ETSI EN 304 620 is to establish essential cybersecurity requirements for VPN services, in line with the EU’s upcoming Cyber Resilience Act (CRA).
The standard aims to improve the level of security for both consumers and businesses through clear requirements for, among other things, encryption, authentication, and vulnerability management by VPN providers. This work marks an important step towards a more secure digital infrastructure within the EU.
This is a new work item pending approval by WGSA via voting.
You are welcome to comment by the 23rd of July!


